CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
50.9%
A bug was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Mageia | 8 | noarch | docker-containerd | < 1.5.7-1 | docker-containerd-1.5.7-1.mga8 |
bugs.mageia.org/show_bug.cgi?id=29268
github.com/containerd/containerd/security/advisories/GHSA-c2h3-6mxw-7mvq
github.com/containerd/containerd/security/advisories/GHSA-c72p-9xmj-rx3w
lists.fedoraproject.org/archives/list/[email protected]/thread/DDMNDPJJTP3J5GOEDB66F6MGXUTRG3Y3/
lists.fedoraproject.org/archives/list/[email protected]/thread/M7ZZTABKTSJ5DYVDIQ7CVZG5HABGM2EC/
lists.opensuse.org/archives/list/[email protected]/thread/KOVJMTDKAFMTONFNVO7Z327OFE52V7FK/
lists.suse.com/pipermail/sle-security-updates/2021-October/009566.html
ubuntu.com/security/notices/USN-5012-1
ubuntu.com/security/notices/USN-5100-1
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
50.9%